Breaking News – Cyber Threats – 2026-09-25 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-25 08:00 PDT
- OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
BleepingComputer • 2026-09-25 07:54 • www.bleepingcomputer.com
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it’s unclear when it’ll begin rolling out. […]
https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-a-500-chatgpt-pro-max-plan-with-faster-codex/ - With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
BleepingComputer • 2026-09-25 07:51 • www.bleepingcomputer.com
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. […]
https://www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/ - A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
SANS ISC Diary (full) • 2026-09-25 05:45 • isc.sans.eduIntroduction
- Microsoft plans to deprecate Windows Deployment Services
BleepingComputer • 2026-09-25 05:40 • www.bleepingcomputer.com
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-windows-deployment-services-after-windows-server-2025/ - Rydox marketplace admin pleads guilty, faces 22 years in prison
BleepingComputer • 2026-09-25 04:35 • www.bleepingcomputer.com
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. […]
https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/ - The SOC Doesn't Need to Start Over with Every Alert
The Hacker News • 2026-09-25 04:30 • thehackernews.com
Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry.The routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading,
https://thehackernews.com/2026/09/the-soc-doesnt-need-to-start-over-with.html - On Anthropic’s AI Misuse Report
Schneier on Security • 2026-09-25 04:07 • www.schneier.comEarlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.
A few of the highlights:
- AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans select…
https://www.schneier.com/blog/archives/2026/09/on-anthropics-ai-misuse-report.html - Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
The Hacker News • 2026-09-25 03:35 • thehackernews.com
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.“At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets,” BitGet said in a post shared on X. “Bitget’s cold wallets and the overwhelming majority of platform assets remain
https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html - Microsoft: Recent Windows updates cause desktop loading issues
BleepingComputer • 2026-09-25 03:30 • www.bleepingcomputer.com
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/ - Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Hacker News • 2026-09-25 03:14 • thehackernews.com
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
The issue stems from a preg_replace() backslash
https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.
- AI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans select…